Hi Tobias,

After disabling the pfkey plugin compilation sha256_96=yes worked. I was
able to see the key length 96 bit using the command "ip xfrm state"

Thanks for the support.

Regards,
Obi

On Wed, Oct 27, 2021 at 11:10 AM Tobias Brunner <tob...@strongswan.org>
wrote:

> Hi Obi,
>
> > Is there a way to check
> > this during runtime?
>
> ipsec statusall
>
> > How to go about from here if pfkey is used to support the
> > AUTH_HMAC_SHA2_256_96 algorithm?
>
> Disable it, you don't want to use it on Linux.
>
> Regards,
> Tobias
>

Reply via email to